Live data from Hacker News

Most websites don't need cookie consent banners

block81.com

51–60 of 103 posts

Re: Most websites don't need cookie consent banners

#51

Earlier quoted context omitted.

> Simply saying "oh I'm only tracking local cookies" might not even be enough in GDPR because the act of writing any cookie is actually covered under the law You're mixing GDPR up with the ePrivacy Directive (henceforth "ePrivacy", not to be confused with the proposed ePrivacy Regulation). GDPR Recital 30 describes how cookies should be understood in relation to the GDPR (to the extent that GDPR Article 4(1) didn't a…

> I'm available to discuss this further, if that would be helpful. That would not be helpful, because the whole business of "consent management" is to provide plausible deniability and the illusion of compliance to businesses without actually making them comply (since complying with the GDPR would incur significant cost and obsolete most of the marketing/analytics team's jobs). I'm very sure they perfectly know what…

I'm pleased when there's at least one configuration that isn't in breach of the regulations. Sadly, many providers don't even manage that.

Re: Most websites don't need cookie consent banners

#52

I wonder how many people provide consent through these banners. Is it frequent enough to be worth the terrible user experience? I know some sites use dark patterns in their cookie banners, which I consider to be a helpful hint that the company doesn't respect the users.

I have been on a call with a CMP where they got mad at me for not resetting our user's preferences and because our 'do not accept' was high due to the fact i refused to de-promote it via a dark pattern. I kid you not.

fwiw; looking at our stats for the past year: No consent: 40.8% Full Consent: 31% Just closed the damn window: 28.1% Went through the nightmare selector: 0.07%

~1.5M impressions from GDPR areas

Re: Most websites don't need cookie consent banners

#53

I wonder how many people provide consent through these banners. Is it frequent enough to be worth the terrible user experience? I know some sites use dark patterns in their cookie banners, which I consider to be a helpful hint that the company doesn't respect the users.

Considering that for most banners the "consent" is the easy option I assume a lot. People want to get rid of the banners. However I claim the point of the bad UX is to make users angry and then have them complain about EU etc. "demanding" those. In order to weaken the regulation of tracking. If they are successful (and they are making progress) "no more cookie banners" is a lot better headlines than "more tracking"

The failure of the EU was to not write into (an updated version of the law) that setting a specific HTTP header means "no", and "no" means "no" not "show me a popup to ask" (i.e. showing a popup in such cases would not be allowed).

Re: Most websites don't need cookie consent banners

#54

Earlier quoted context omitted.

I appreciate your precision. Most folks, unless discussing specific provisions, just use GDPR as an umbrella term, much like the CCPA is still used and inclusive of CPRA.

This response sounds suspiciously like competence. Do you mind disclosing which consent provider you work for, so I can have a look? (I only ever found one consent product I was really happy with, and it shut down a few months after I discovered it.)

It's DataGrail. I don't mind disclosing it, but I was kinda hoping not to because I'm really not here to advertise... I guess I won't say I know the subject, but do have some experience. lol.

I'd be happy to discuss directly if you want. Not sure how to exchange details if you're interested but we can figure something out I guess.

Re: Most websites don't need cookie consent banners

#55

I consider all those pop-ups to be illegal. The use case in my opinion does not warrant pissing off users by distracting them via such pop-ups. Here I classify slide-ins the same as pop-ups. I don't even read what is written there since I already don't care. I kind of have to use extensions to workaround this spam. The EU bureaucrats are very confused here - they cost a lot of money and don't really improve much at a…

[dead]

Re: Most websites don't need cookie consent banners

#56

Earlier quoted context omitted.

Considering that for most banners the "consent" is the easy option I assume a lot. People want to get rid of the banners. However I claim the point of the bad UX is to make users angry and then have them complain about EU etc. "demanding" those. In order to weaken the regulation of tracking. If they are successful (and they are making progress) "no more cookie banners" is a lot better headlines than "more tracking"

The failure of the EU was to not write into (an updated version of the law) that setting a specific HTTP header means "no", and "no" means "no" not "show me a popup to ask" (i.e. showing a popup in such cases would not be allowed).

It wouldn't matter because most of the consent flows you see are already not compliant. The problem is a perpetual lack of enforcement even for the blatant breaches. An HTTP header wouldn't change the situation, websites would still ignore it and still get away with it.

Re: Most websites don't need cookie consent banners

#58
post #6

"Advertising or behavioral tracking cookies" Any real business needs to do behavioral tracking for campaign conversions, add-to-cart, customer acquisition, funneling, retention, personalization, etc. I love how we all hate cookie banners and say they are unnecessary, but are salaries are all paid by apps that do behavioral tracking. Only hobby blogs can get by without it.

I appreciate the list of reasons to cookies are useful. Despite having worked in technology for 25 years, I couldn't have articulated that list off the top of my head. I have never worked for a website that made money that way. I think that means not ALL websites need invasive tracking.

> website that made money that way

Some of those scenarios are dubious as to whether they actually bring profit and "make money". They can very well be a net loss and are merely there to justify the job of the advertising/marketing/analytics/etc team, who is conveniently charge of crunching those numbers and obviously would never put any adverse numbers forward.

Same thing in advertising - there's a lot of middlemen in the industry that are happy to take their cut, cook the numbers and look the other way despite no actual impact on sales.

So while I don't disagree these things can make money when in the right hands and done in moderation, the reality is that there's a shit ton of waste and deadweight in the industry. It may very well be that the actual (vs self-reported) profit from ad/marketing efforts is negative and merely covers the paychecks of said ad/marketing teams.

Re: Most websites don't need cookie consent banners

#59
post #40
post #23

Earlier quoted context omitted.

You don't seem to understand that one can do behavioral tracking without sharing all personal data with Facebook and Google. GDPR is mainly focused on who you share the data with. Performance tracking of core business processess including traffic sources can be done without involvement of Facebook and Google. It's totally legit to spend a career helping the folks at Facebook and Google to soak up more private informa…

No thats not true

Disagreed. You can absolutely do all analytics, personalization and marketing in-house on your properties. You only need data sharing if you want to influence advertising on other properties or if you display others' ads on yours.

Whether you want to do so is a different matter. This obviously requires (potentially custom) software and infrastructure, vs throwing in GTM and calling it a day. If there is no regulatory reason for it (there isn't - this aspect of the GDPR is not enforced), most businesses won't bother and will take the easy option.

Post reply on HN